CVE-2026-34676: Substance3D - Painter | Out-of-bounds Write (CWE-787)
Published May 12, 2026
·Updated
Substance3D - Painter versions 12.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
2 affected components
Adobe Substance 3D Painter<=12.0.2
Adobe Substance 3D Painter<12.0.3
Event History
May 12, 2026
CVE Published
via MITRE·05:42 PM
Data Sourced
via MITRE·05:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-34676?
CVE-2026-34676 is considered high severity due to the potential for arbitrary code execution.
2
How do I fix CVE-2026-34676?
To fix CVE-2026-34676, update Adobe Substance 3D Painter to version 12.0.3 or later.
3
What versions of Adobe Substance 3D Painter are affected by CVE-2026-34676?
CVE-2026-34676 affects Adobe Substance 3D Painter versions 12.0.2 and earlier.
4
What type of vulnerability is CVE-2026-34676?
CVE-2026-34676 is an out-of-bounds write vulnerability classified under CWE-787.
5
What is required for exploitation of CVE-2026-34676?
Exploitation of CVE-2026-34676 requires user interaction, making it more accessible to attackers.